germanenburi | 24.09.2016 22:13 | Hallo Jürgen!
Mein E-Mail-Provider ist inode.
Leider habe ich nach dem download von Anti-Malware zuerst die Anleitung und dann erst Deine weiteren Hinweise gelesen. Nun hatte ich den Haken bei "Suche nach Rootkits" nicht gesetzt. Nachdem ich die Funde bereits in Quarantäne verschoben hatte, habe ich den Suchlauf danach ein zweites Mal durchgeführt (nun mit der "Suche nach Rootkits") und poste dieses Protokoll nun als mbamlog02.txt. Ich hoffe, das war nicht ganz verkehrt!
mbamlog: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 24.09.2016
Suchlaufzeit: 20:47
Protokolldatei: mbamlog.txt
Administrator: Ja
Version: 2.2.1.1043
Malware-Datenbank: v2016.09.24.04
Rootkit-Datenbank: v2016.08.15.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: PETER
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 370618
Abgelaufene Zeit: 8 Min., 53 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [b44062132773df571c4dbb0e61a1966a],
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2F23AB71-4AC6-41F2-A955-EA576E553146}, In Quarantäne, [51a397deb7e34fe7c2a71daca9592cd4],
PUP.Optional.WinYahoo, HKU\S-1-5-21-3491398124-3717858485-255693985-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472F-A0FF-E1416B8B2E3A}, In Quarantäne, [d321f87d0199171f4793d1fefa080af6],
PUP.Optional.WinYahoo, HKU\S-1-5-21-3491398124-3717858485-255693985-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2F23AB71-4AC6-41F2-A955-EA576E553146}, In Quarantäne, [cb29e4912d6dd5615387c30cbd45ef11],
PUP.Optional.ProductSetup, HKU\S-1-5-21-3491398124-3717858485-255693985-1001\SOFTWARE\PRODUCTSETUP, In Quarantäne, [47adcbaa811994a28f37aa06da2958a8],
Registrierungswerte: 10
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f[1cd87bfac5d51125b4f4c7f53acae51b]D1%26b[1cd87bfac5d51125b4f4c7f53acae51b]DIE%26cc[1cd87bfac5d51125b4f4c7f53acae51b]Dat%26pa[1cd87bfac5d51125b4f4c7f53acae51b]DWincy%26cd[1cd87bfac5d51125b4f4c7f53acae51b]D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr[1cd87bfac5d51125b4f4c7f53acae51b]D1784489580%26a[1cd87bfac5d51125b4f4c7f53acae51b]Dwbf_popjar_16_09_ssg02%26os_ver[1cd87bfac5d51125b4f4c7f53acae51b]D6.1%26os[1cd87bfac5d51125b4f4c7f53acae51b]DWindowsIn QuarantäneB7In QuarantäneBProfessional, %4, %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, https://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_01¶m1=1¶m2=f[b44062132773df571c4dbb0e61a1966a]D4%26b[b44062132773df571c4dbb0e61a1966a]DIE%26cc[b44062132773df571c4dbb0e61a1966a]Dat%26pa[b44062132773df571c4dbb0e61a1966a]DWincy%26cd[b44062132773df571c4dbb0e61a1966a]D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyEyBtDtN1L2XzutAtFtCyCtFtCtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyBtA0CzztD0D0D0AtGyEyC0B0EtG0F0B0E0CtGtCyEyD0FtGtDzy0CzytDyDtAyByDzz0FtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtBzyyB%26cr[b44062132773df571c4dbb0e61a1966a]D1567203828%26a[b44062132773df571c4dbb0e61a1966a]Dwbf_popjar_16_01%26os_ver[b44062132773df571c4dbb0e61a1966a]D6.1%26os[b44062132773df571c4dbb0e61a1966a]DWindowsIn QuarantäneB7In QuarantäneBProfessional&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, https://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_01¶m1=1¶m2=f[01f391e48515be78b6b3c10862a0fc04]D4%26b[01f391e48515be78b6b3c10862a0fc04]DIE%26cc[01f391e48515be78b6b3c10862a0fc04]Dat%26pa[01f391e48515be78b6b3c10862a0fc04]DWincy%26cd[01f391e48515be78b6b3c10862a0fc04]D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyEyBtDtN1L2XzutAtFtCyCtFtCtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyBtA0CzztD0D0D0AtGyEyC0B0EtG0F0B0E0CtGtCyEyD0FtGtDzy0CzytDyDtAyByDzz0FtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtBzyyB%26cr[01f391e48515be78b6b3c10862a0fc04]D1567203828%26a[01f391e48515be78b6b3c10862a0fc04]Dwbf_popjar_16_01%26os_ver[01f391e48515be78b6b3c10862a0fc04]D6.1%26os[01f391e48515be78b6b3c10862a0fc04]DWindowsIn QuarantäneB7In QuarantäneBProfessional&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2f23ab71-4ac6-41f2-a955-ea576e553146}|URL, https://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f[51a397deb7e34fe7c2a71daca9592cd4]D4%26b[51a397deb7e34fe7c2a71daca9592cd4]DIE%26cc[51a397deb7e34fe7c2a71daca9592cd4]Dat%26pa[51a397deb7e34fe7c2a71daca9592cd4]DWincy%26cd[51a397deb7e34fe7c2a71daca9592cd4]D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr[51a397deb7e34fe7c2a71daca9592cd4]D1784489580%26a[51a397deb7e34fe7c2a71daca9592cd4]Dwbf_popjar_16_09_ssg02%26os_ver[51a397deb7e34fe7c2a71daca9592cd4]D6.1%26os[51a397deb7e34fe7c2a71daca9592cd4]DWindowsIn QuarantäneB7In QuarantäneBProfessional&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2f23ab71-4ac6-41f2-a955-ea576e553146}|TopResultURLFallback, https://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f[39bb2d4872281e181950eedbb64cc739]D4%26b[39bb2d4872281e181950eedbb64cc739]DIE%26cc[39bb2d4872281e181950eedbb64cc739]Dat%26pa[39bb2d4872281e181950eedbb64cc739]DWincy%26cd[39bb2d4872281e181950eedbb64cc739]D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr[39bb2d4872281e181950eedbb64cc739]D1784489580%26a[39bb2d4872281e181950eedbb64cc739]Dwbf_popjar_16_09_ssg02%26os_ver[39bb2d4872281e181950eedbb64cc739]D6.1%26os[39bb2d4872281e181950eedbb64cc739]DWindowsIn QuarantäneB7In QuarantäneBProfessional&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-3491398124-3717858485-255693985-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|URL, https://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_01¶m1=1¶m2=f[d321f87d0199171f4793d1fefa080af6]D4%26b[d321f87d0199171f4793d1fefa080af6]DIE%26cc[d321f87d0199171f4793d1fefa080af6]Dat%26pa[d321f87d0199171f4793d1fefa080af6]DWincy%26cd[d321f87d0199171f4793d1fefa080af6]D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyEyBtDtN1L2XzutAtFtCyCtFtCtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyBtA0CzztD0D0D0AtGyEyC0B0EtG0F0B0E0CtGtCyEyD0FtGtDzy0CzytDyDtAyByDzz0FtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtBzyyB%26cr[d321f87d0199171f4793d1fefa080af6]D1567203828%26a[d321f87d0199171f4793d1fefa080af6]Dwbf_popjar_16_01%26os_ver[d321f87d0199171f4793d1fefa080af6]D6.1%26os[d321f87d0199171f4793d1fefa080af6]DWindowsIn QuarantäneB7In QuarantäneBProfessional&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-3491398124-3717858485-255693985-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}|TopResultURLFallback, https://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_01¶m1=1¶m2=f[1dd7215468327abcf1e9933cb151eb15]D4%26b[1dd7215468327abcf1e9933cb151eb15]DIE%26cc[1dd7215468327abcf1e9933cb151eb15]Dat%26pa[1dd7215468327abcf1e9933cb151eb15]DWincy%26cd[1dd7215468327abcf1e9933cb151eb15]D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyEyBtDtN1L2XzutAtFtCyCtFtCtFtDtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyBtA0CzztD0D0D0AtGyEyC0B0EtG0F0B0E0CtGtCyEyD0FtGtDzy0CzytDyDtAyByDzz0FtB2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtBzyyB%26cr[1dd7215468327abcf1e9933cb151eb15]D1567203828%26a[1dd7215468327abcf1e9933cb151eb15]Dwbf_popjar_16_01%26os_ver[1dd7215468327abcf1e9933cb151eb15]D6.1%26os[1dd7215468327abcf1e9933cb151eb15]DWindowsIn QuarantäneB7In QuarantäneBProfessional&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-3491398124-3717858485-255693985-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2f23ab71-4ac6-41f2-a955-ea576e553146}|URL, https://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f[cb29e4912d6dd5615387c30cbd45ef11]D4%26b[cb29e4912d6dd5615387c30cbd45ef11]DIE%26cc[cb29e4912d6dd5615387c30cbd45ef11]Dat%26pa[cb29e4912d6dd5615387c30cbd45ef11]DWincy%26cd[cb29e4912d6dd5615387c30cbd45ef11]D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr[cb29e4912d6dd5615387c30cbd45ef11]D1784489580%26a[cb29e4912d6dd5615387c30cbd45ef11]Dwbf_popjar_16_09_ssg02%26os_ver[cb29e4912d6dd5615387c30cbd45ef11]D6.1%26os[cb29e4912d6dd5615387c30cbd45ef11]DWindowsIn QuarantäneB7In QuarantäneBProfessional&p={searchTerms}, %4, %5
PUP.Optional.WinYahoo, HKU\S-1-5-21-3491398124-3717858485-255693985-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2f23ab71-4ac6-41f2-a955-ea576e553146}|TopResultURLFallback, https://at.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f[df15680de3b71323eaf07f50ca38d828]D4%26b[df15680de3b71323eaf07f50ca38d828]DIE%26cc[df15680de3b71323eaf07f50ca38d828]Dat%26pa[df15680de3b71323eaf07f50ca38d828]DWincy%26cd[df15680de3b71323eaf07f50ca38d828]D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr[df15680de3b71323eaf07f50ca38d828]D1784489580%26a[df15680de3b71323eaf07f50ca38d828]Dwbf_popjar_16_09_ssg02%26os_ver[df15680de3b71323eaf07f50ca38d828]D6.1%26os[df15680de3b71323eaf07f50ca38d828]DWindowsIn QuarantäneB7In QuarantäneBProfessional&p={searchTerms}, %4, %5
PUP.Optional.ProductSetup, HKU\S-1-5-21-3491398124-3717858485-255693985-1001\SOFTWARE\PRODUCTSETUP|tb, 0R0DtO0U1C1S1U1StR0J1Q2P1J1K1I2R, In Quarantäne, [47adcbaa811994a28f37aa06da2958a8]
Registrierungsdaten: 1
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, https://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=fSchlecht: (https://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dat%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr%3D1784489580%26a%3Dwbf_popjar_16_09_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),Ersetzt,[43b10c69277370c6112c2c4dab592fd1]D1%26bSchlecht: (https://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dat%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr%3D1784489580%26a%3Dwbf_popjar_16_09_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),Ersetzt,[43b10c69277370c6112c2c4dab592fd1]DIE%26ccSchlecht: (https://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dat%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr%3D1784489580%26a%3Dwbf_popjar_16_09_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),Ersetzt,[43b10c69277370c6112c2c4dab592fd1]Dat%26paSchlecht: (https://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dat%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr%3D1784489580%26a%3Dwbf_popjar_16_09_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),Ersetzt,[43b10c69277370c6112c2c4dab592fd1]DWincy%26cdSchlecht: (https://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dat%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr%3D1784489580%26a%3Dwbf_popjar_16_09_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),Ersetzt,[43b10c69277370c6112c2c4dab592fd1]D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26crSchlecht: (https://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dat%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr%3D1784489580%26a%3Dwbf_popjar_16_09_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),Ersetzt,[43b10c69277370c6112c2c4dab592fd1]D1784489580%26aSchlecht: (https://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dat%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr%3D1784489580%26a%3Dwbf_popjar_16_09_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),Ersetzt,[43b10c69277370c6112c2c4dab592fd1]Dwbf_popjar_16_09_ssg02%26os_verSchlecht: (https://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dat%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr%3D1784489580%26a%3Dwbf_popjar_16_09_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),Ersetzt,[43b10c69277370c6112c2c4dab592fd1]D6.1%26osSchlecht: (https://at.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_popjar_16_09_ssg02¶m1=1¶m2=f%3D1%26b%3DIE%26cc%3Dat%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0C0EtA0DzztBzy0E0CtD0BtDzzyEtDzytN0D0Tzu0StCyDtBtBtN1L2XzutAtFtCzztFtCtFtCtN1L1Czu1StN1L1G1B1V1N2Y1L1Qzu2SyCtBzy0Fzy0B0C0DtGyCtD0C0CtGzzyE0D0FtGtAtB0C0AtGzztA0B0CyC0F0C0AtDyC0BtD2QtN1M1F1B2Z1V1N2Y1L1Qzu2SzyyB0B0AyBzy0ByEtGtCtByByCtGyE0A0B0CtGzy0DyE0EtG0AyDtAyCzyyCzz0DyD0EtDzz2QtN0A0LzuyE%26cr%3D1784489580%26a%3Dwbf_popjar_16_09_ssg02%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional),Ersetzt,[43b10c69277370c6112c2c4dab592fd1]DWindowsGut: (www.google.com)B7Gut: (www.google.com)BProfessional, %4, %5
Ordner: 1
PUP.Optional.PCSpeedMaximizer, C:\Users\PETER\Documents\PC Speed Maximizer, In Quarantäne, [fcf835406e2c56e0eb20c6e982817f81],
Dateien: 3
PUP.Optional.InstallCore, C:\Users\PETER\Downloads\JavaSetup(1).exe, In Quarantäne, [d420db9a8e0c59ddfa25931836cbeb15],
PUP.Optional.PCSpeedMaximizer, C:\Users\PETER\Documents\PC Speed Maximizer\CookieExclusions.txt, In Quarantäne, [fcf835406e2c56e0eb20c6e982817f81],
PUP.Optional.WinYahoo, C:\Users\PETER\AppData\Roaming\Mozilla\Firefox\Profiles\blznwxg2.default\searchplugins\Search Provided by Yahoo.xml, In Quarantäne, [e80c5025b5e5b28437201c807b8948b8],
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) mbamlog02: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlaufdatum: 24.09.2016
Suchlaufzeit: 21:17
Protokolldatei: mbamlog02.txt
Administrator: Ja
Version: 2.2.1.1043
Malware-Datenbank: v2016.09.24.04
Rootkit-Datenbank: v2016.08.15.01
Lizenz: Testversion
Malware-Schutz: Aktiviert
Schutz vor bösartigen Websites: Aktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows 10
CPU: x64
Dateisystem: NTFS
Benutzer: PETER
Suchlauftyp: Bedrohungssuchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 372120
Abgelaufene Zeit: 12 Min., 35 Sek.
Speicher: Aktiviert
Start: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Aktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(keine bösartigen Elemente erkannt)
Module: 0
(keine bösartigen Elemente erkannt)
Registrierungsschlüssel: 0
(keine bösartigen Elemente erkannt)
Registrierungswerte: 0
(keine bösartigen Elemente erkannt)
Registrierungsdaten: 0
(keine bösartigen Elemente erkannt)
Ordner: 0
(keine bösartigen Elemente erkannt)
Dateien: 0
(keine bösartigen Elemente erkannt)
Physische Sektoren: 0
(keine bösartigen Elemente erkannt)
(end) ESET: Code:
ESETSmartInstaller@High as downloader log:
all ok
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=ce7d80e332295047830085266aceb108
# end=init
# utc_time=2016-09-24 07:46:52
# local_time=2016-09-24 09:46:52 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
Update Init
Update Download
Update Finalize
Updated modules version: 30861
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# EOSSerial=ce7d80e332295047830085266aceb108
# end=updated
# utc_time=2016-09-24 07:49:52
# local_time=2016-09-24 09:49:52 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# osver=6.2.9200 NT
# product=EOS
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7777
# api_version=3.1.1
# EOSSerial=ce7d80e332295047830085266aceb108
# engine=30861
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2016-09-24 08:40:49
# local_time=2016-09-24 10:40:49 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1031
# osver=6.2.9200 NT
# compatibility_mode_1=''
# compatibility_mode=5893 16776573 100 94 8351 28563792 0 0
# scanned=290966
# found=11
# cleaned=0
# scan_time=3056
sh=F50196E0DE589DD081E98B6EDFAE64D18AF0D7CF ft=1 fh=e5d896ad14d6f079 vn="Win32/BrowseFox.DG evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Middle Rush\Uninstaller.exe.vir"
sh=0A0E48B405FDB280E4CE1651ABF9EDC1B8C59A86 ft=1 fh=d1c44ecf9dd20ce9 vn="Variante von Win32/BrowseFox.CJ evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Middle Rush\Extensions\d00ab4cc-662c-40b6-a85f-d53086f4bb16.dll.vir"
sh=05AC6F74D0525D425ECFEE871A735A0A748DBFB2 ft=0 fh=0000000000000000 vn="JS/BrowseFox.A evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Middle Rush\Extensions\{ace83c07-e68e-416d-b137-ea154fb6de9f}.xpi.vir"
sh=53668A95C2E90063A74EE1CF0B5B424C05A98F84 ft=1 fh=34682e738d8106df vn="Variante von Win32/AdWare.SpeedingUpMyPC.S Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\PC Speed Maximizer\PCSpeedMaximizer.exe.vir"
sh=9C8A41536CC6BE035D2F8610FF3A2B457E46DBE6 ft=1 fh=c0f0e1963dbe99a8 vn="Variante von Win32/Adware.SpeedingUpMyPC.AS Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\PC Speed Maximizer\SPMSchedule.exe.vir"
sh=352D94006557FFE56D0B3D4A3D53A33E1EDAA13B ft=1 fh=9c2deb251acdf724 vn="Variante von Win32/Systweak.R evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\WinZip Driver Updater\winzipdu.exe.vir"
sh=928A536FBFF196495B90E4BD51B932485B84A099 ft=1 fh=748b6a41a833329e vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\PETER\AppData\Local\Temp\DMR\dmr_72.exe"
sh=A4E33857D821EB0F9F7F11E3962E473A6B739121 ft=1 fh=cb178d453773295a vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\PETER\Downloads\Nitro PDF Reader 64 Bit - CHIP-Installer.exe"
sh=BD31A474ABDA7A6ED1A2CF667DA740EF2CCC89C3 ft=1 fh=f51206bd6d1a7512 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\PETER\Downloads\Snipping Tool Plus - CHIP-Installer.exe"
sh=91C19C05AA8FBD37D982146AF848F4B1D065320C ft=1 fh=e62187eae0c63a97 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\PETER\Downloads\Sudoku Assistenten - CHIP-Installer.exe"
sh=547F1ED85589AF46762AE85237C4B0294EB5E841 ft=1 fh=f5d89b1e23ae1387 vn="Variante von Win32/Adware.Coupons.AA Anwendung" ac=I fn="C:\Users\PETER\Downloads\HP Downloads\HP Photosmart Plus All-in-One Druckerserie, B209 –Software und Treiber für alle Funktionen - PS_AIO_06_B209a-m_USW_Full_Win_WW_140_175-4.exe" Tut mir Leid, wegen des Irrtums!
LG, Peter |